Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | java redirect being appended to html


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Internet Discussion

java redirect being appended to html
Reply
 
Thread Tools
Old 24-04-2008, 18:32   #1
NINJA
 
grandmaster's Avatar
 
Join Date: May 2005
Location: Nr Manchester
Age: 30
Posts: 882
grandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of society
java redirect being appended to html

I run a website and my index and home page keeps having javascript appended to it. (that redirects the user to some russian spyware site ) and I refuse to get my users infected.

I have contacted my webhost who gave me a scripted reply that I was not happy with.

I have changed my passwords twice now and they are 20+ characters with upper and lower case and no word is in the dictionary. ( they said my password may have been bruteforced.. but the previous password was just as strong)

my web host refuse to admit that the server has a problem ( I believe they have a rogue script from another account on there)

But basically this is the 9th time this has happened and I'm getting sick of it .
Does anyone know a way that I can secure my index.html from being modified (the permissions are set to 0644)
I'm getting bored from the lack of response from my webhost and if they dont change their tune soon i'll be walking at taking all my business with me.

Any advice would be nice..

All the best

Ryan
__________________
Scuba Diver?
Our new site for scuba divers.
http://www.britishclubdivers.co.uk
2nd Dan Black belt in W.J.J.F Jujitsu.

Last edited by grandmaster; 24-04-2008 at 18:37.
grandmaster is offline   Reply With Quote
Old 24-04-2008, 18:37   #2
AWAY (HOLIDAY)
 
Paul M's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 45
Services: ntl Phone : Sky+ (with multiroom) : ntl Cable (20 Mbps)
Posts: 14,322
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Send a message via ICQ to Paul M
Re: java redirect being appended to html

I wouldnt wait, move host now. Someone clearly has acesss to the files to exploit them and the host doesnt seem to care.
__________________
DigiGuide Click here for a real, interactive, tv guide.
Paul M is offline   Reply With Quote
Old 24-04-2008, 18:57   #3
while(!naked){--clothes}
 
ikthius's Avatar
 
Join Date: Mar 2004
Location: Glasgow, Scotland
Services: anything for a new job
Posts: 3,950
ikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze array
ikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze array
Re: java redirect being appended to html

is the java in your html?

or is there a bit of code in your site somewhere?

but if you keep changing your password, it sounds like there is code stealing your password everytime you change it, try going through your site thoroughly to extract the code/program then try a new password, if it comes back it really is s problem with the host.

ik
__________________
Let me guess, you picked out yet another colorful box with a crank that I'm expected to turn and turn until OOP! big shock, a jack pops out and you laugh and the kids laugh and the dog laughs and I die a little inside.
ikthius is offline   Reply With Quote
Old 24-04-2008, 19:02   #4
NINJA
 
grandmaster's Avatar
 
Join Date: May 2005
Location: Nr Manchester
Age: 30
Posts: 882
grandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of society
Re: java redirect being appended to html

Thanks Paul i'm looking at Voo servers as an alternative..

ik:
The site in question is static html.. index.html.

I wont wont post the script on here for obvious reasons but it starts avaScript>function bban(x){var l=x.length,b=1024,i,j,r,p= etc etc and it should not be in my html.

I have uploaded my clean index I just wonder how long it will last.
__________________
Scuba Diver?
Our new site for scuba divers.
http://www.britishclubdivers.co.uk
2nd Dan Black belt in W.J.J.F Jujitsu.
grandmaster is offline   Reply With Quote
Old 24-04-2008, 21:35   #5
NINJA
 
grandmaster's Avatar
 
Join Date: May 2005
Location: Nr Manchester
Age: 30
Posts: 882
grandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of society
Re: java redirect being appended to html

If anyone knows how they are managing to edit these files i would love to know.
pm me please, might help me convince the server company to sort it out.

Ry
__________________
Scuba Diver?
Our new site for scuba divers.
http://www.britishclubdivers.co.uk
2nd Dan Black belt in W.J.J.F Jujitsu.
grandmaster is offline   Reply With Quote
Old 24-04-2008, 21:45   #6
Anyone can play guitar
 
Mr_love_monkey's Avatar
 
Join Date: Jun 2003
Location: London way
Age: 32
Services: Women for money
Posts: 6,138
Mr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny star
Mr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny star
Send a message via Yahoo to Mr_love_monkey
Re: java redirect being appended to html

Not part of the massive web infection that is going on is it?

http://www.theregister.co.uk/2008/04...ss_web_attack/
http://www.theregister.co.uk/2008/01...web_infection/
http://www.channelregister.co.uk/200...ion_continues/
__________________
Cheap Domain Name Registration & Reliable Hosting

All because of you, I haven't slept in so long.
When I do, I dream of drowning in the ocean;
Mr_love_monkey is online now   Reply With Quote
Old 24-04-2008, 22:57   #7
NINJA
 
grandmaster's Avatar
 
Join Date: May 2005
Location: Nr Manchester
Age: 30
Posts: 882
grandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of society
Re: java redirect being appended to html

in fact if there are any php gurus out there that could help me that would be even better,

If I had a script that monitored the size of the index.html and home.html (or any html for that matter ) and somehow alerted me that the size had changed that would help.

Because i'm a programming tard it would take me waaay to long to come up with , write,test a script but i'm sure one of you loverly script writers could know up something in no time.

If you have time to help i would be eternally grateful!

---------- Post added at 21:50 ---------- Previous post was at 21:47 ----------

Could well be.
I would love to get one of these guys in a room with no windows or cameras

Quote:
Originally Posted by Mr_love_monkey View Post
---------- Post added at 22:36 ---------- Previous post was at 21:50 ----------

ahaa bisto,after some searching around I have found one that does the job.
If anyone wants it let me know.

ryan

---------- Post added at 22:57 ---------- Previous post was at 22:36 ----------

ok for anyone that cares

I have now got a php script that looks at the file size of the main file.
a cron job will run the script and email me if the size changes.. cool huh.

Again if anyone would like the script let me know..

Ryan
__________________
Scuba Diver?
Our new site for scuba divers.
http://www.britishclubdivers.co.uk
2nd Dan Black belt in W.J.J.F Jujitsu.
grandmaster is offline   Reply With Quote
Old 25-04-2008, 07:08   #8
while(!naked){--clothes}
 
ikthius's Avatar
 
Join Date: Mar 2004
Location: Glasgow, Scotland
Services: anything for a new job
Posts: 3,950
ikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze array
ikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze arrayikthius has a bronze array
Re: java redirect being appended to html

Quote:
Originally Posted by grandmaster View Post
i<snip>

ok for anyone that cares

I have now got a php script that looks at the file size of the main file.
a cron job will run the script and email me if the size changes.. cool huh.

Again if anyone would like the script let me know..

Ryan
hope it works, but seriously, why put up with it happening all the time, make sure there are no nasty scripts in your folders within your space. clean out your folders, make sure its clean, change your password and inform the host company what you have done and when you have done it, and let them know it is totally clean, then if it happens again, you can then tell them they have the problem. and insist they investigate, or you may be looking at another i-web situ.

ik
__________________
Let me guess, you picked out yet another colorful box with a crank that I'm expected to turn and turn until OOP! big shock, a jack pops out and you laugh and the kids laugh and the dog laughs and I die a little inside.
ikthius is offline   Reply With Quote
Old 25-04-2008, 09:02   #9
NINJA
 
grandmaster's Avatar
 
Join Date: May 2005
Location: Nr Manchester
Age: 30
Posts: 882
grandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of societygrandmaster is a pillar of society
Re: java redirect being appended to html

Thanks for the reply ik,

I'm going to change servers I think and just use the remaining time on these to test stuff.
Thing is like just before all this happened I bought another 12 month account with them figures.....

Anyhoo I'm all clean now and I can keep my eye on this and I will be implementing this script across all my sites.

Just gutted that I have to keep throwing money at it, first I-web, now these.
Its not like these sites are even very popular .

I appreciate you taking the time to reply though :O)
__________________
Scuba Diver?
Our new site for scuba divers.
http://www.britishclubdivers.co.uk
2nd Dan Black belt in W.J.J.F Jujitsu.
grandmaster is offline   Reply With Quote
Old 25-04-2008, 09:10   #10
The Music Guy
 
Join Date: Nov 2007
Location: Belfast
Age: 25
Services: VM M BB, VM XL TV and M Phone
Posts: 818
PeteTheMusicGuy has a brilliant futurePeteTheMusicGuy has a brilliant futurePeteTheMusicGuy has a brilliant futurePeteTheMusicGuy has a brilliant futurePeteTheMusicGuy has a brilliant futurePeteTheMusicGuy has a brilliant futurePeteTheMusicGuy has a brilliant futurePeteTheMusicGuy has a brilliant futurePeteTheMusicGuy has a brilliant futurePeteTheMusicGuy has a brilliant futurePeteTheMusicGuy has a brilliant futurePeteTheMusicGuy has a brilliant future
Send a message via MSN to PeteTheMusicGuy Send a message via Yahoo to PeteTheMusicGuy
Re: java redirect being appended to html

Deffo move host
PeteTheMusicGuy is offline   Reply With Quote
Old 25-04-2008, 10:07   #11
Eric Cartman Wannabe
 
punky's Avatar
 
Join Date: Jun 2003
Location: Cockney geeza land
Age: 27
Services: c:\> net start punky
Posts: 11,891
punky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver bling
punky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver bling
Re: java redirect being appended to html

Which host was you with?
__________________
"We're not here for a long time, we're here for a good time" - Mike Ness (Social Distortion)
"Reach for the sky, 'cause tomorrow may never come" - Reach For The Sky (Social Distortion)
punky is online now   Reply With Quote
Old 25-04-2008, 13:10   #12
cf.geek
 
webcrawler2050's Avatar
 
Join Date: Feb 2008
Location: Gloucester
Services: V+ VM 20MB VM Fixed Line VM Mobiles
Posts: 581
webcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to behold
Send a message via MSN to webcrawler2050 Send a message via Skype™ to webcrawler2050
Re: java redirect being appended to html

Hmm this isnt the host!!

I guess its something like

<iframe> ashfdashfoah </iframe>

Or script=java injected into your page..

First question.. Does your host use cPanel?
2nd have you asked your host to check the raw access log
3rd: change your password to a random one of numbers and characters
4th: Does your host has FontPage extensions enabled?
5th: Is there a url / ip in the code?
6th: Who is the host
7th: whats your domain

Do not move hosts yet. Theres no point in running as it may happen as your domain could of just be randomly attacked - if you are *desperate* to move host - maybe I / we can help: www.bionic-hosting.co.uk
__________________
Kind Regards
Richard Copestake
Bionic Internet Ltd - UK Web Hosting - UK Reseller Hosting - UK Web Directory
Company No: 6545963

Last edited by webcrawler2050; 25-04-2008 at 13:13.
webcrawler2050 is offline   Reply With Quote
Old 25-04-2008, 13:16   #13
Anyone can play guitar
 
Mr_love_monkey's Avatar
 
Join Date: Jun 2003
Location: London way
Age: 32
Services: Women for money
Posts: 6,138
Mr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny star
Mr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny star
Send a message via Yahoo to Mr_love_monkey
Re: java redirect being appended to html

Quote:
Originally Posted by grandmaster View Post
( they said my password may have been bruteforced.. but the previous password was just as strong)
Personally I find the fact they said that quite worrying - don't they do anything to stop brute force attacks?
__________________
Cheap Domain Name Registration & Reliable Hosting

All because of you, I haven't slept in so long.
When I do, I dream of drowning in the ocean;
Mr_love_monkey is online now   Reply With Quote
Old 25-04-2008, 13:22   #14
cf.geek
 
webcrawler2050's Avatar
 
Join Date: Feb 2008
Location: Gloucester
Services: V+ VM 20MB VM Fixed Line VM Mobiles
Posts: 581
webcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to behold
Send a message via MSN to webcrawler2050 Send a message via Skype™ to webcrawler2050
Re: java redirect being appended to html

Lmao - bruteforce is easy to stop

If run cPanel just turn on Cpanel bruteforce

Anywho its pretty simple - just needs the right knowledge
__________________
Kind Regards
Richard Copestake
Bionic Internet Ltd - UK Web Hosting - UK Reseller Hosting - UK Web Directory
Company No: 6545963
webcrawler2050 is offline   Reply With Quote
Old 25-04-2008, 13:24   #15
Anyone can play guitar
 
Mr_love_monkey's Avatar
 
Join Date: Jun 2003
Location: London way
Age: 32
Services: Women for money
Posts: 6,138
Mr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny star
Mr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny starMr_love_monkey has a nice shiny star
Send a message via Yahoo to Mr_love_monkey
Re: java redirect being appended to html

Quote:
Originally Posted by webcrawler2050 View Post
Lmao - bruteforce is easy to stop

If run cPanel just turn on Cpanel bruteforce

Anywho its pretty simple - just needs the right knowledge
Exactly - I wouldn't put much faith in them if they can't do that
__________________
Cheap Domain Name Registration & Reliable Hosting

All because of you, I haven't slept in so long.
When I do, I dream of drowning in the ocean;
Mr_love_monkey is online now   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 22:56.


Links
Google
 
Web www.cableforum.co.uk